ISO/IEC 29110-3-2:2018
(Main)Systems and software engineering — Lifecycle profiles for Very Small Entities (VSEs) — Part 3-2: Conformity certification scheme
Systems and software engineering — Lifecycle profiles for Very Small Entities (VSEs) — Part 3-2: Conformity certification scheme
This document: - defines the rules applicable for certification of the implementation of systems engineering, software engineering and service delivery processes complying with the requirements given in ISO/IEC 29110‑4-m, Profile specifications; and - provides the necessary information and confidence to customers about the way certification of their suppliers has been granted. Certification of the implementation of systems and software engineering processes (named "certification" in this document) is a third-party conformity assessment activity (see ISO/IEC 17000:2004, 5.5). Bodies performing this activity are therefore third-party conformity assessment bodies (named "certification body/bodies" in this document). NOTE This document is primarily intended to be used as a criteria document for the accreditation or peer assessment of certification bodies which seek to be recognized as being competent to certify that a Very Small Entity (VSE) complies with ISO/IEC 29110‑4-m, Profile Specifications. Some of its requirements could also be found useful by any other parties involved in the conformity assessment of such certification bodies. Systems and software engineering processes certification does not attest the fitness of the systems and or software products offered by a VSE. It is important to note that certification of the implementation of systems and software engineering processes according to ISO/IEC 29110‑4-m, Profile Specifications, is a process certification and not a management systems certification neither a product certification. Certification of the implementation of systems and software engineering processes (SEP) of a very small entity (VSE) is one means of providing assurance that the VSE has implemented systems and software engineering processes to the development or maintenance of systems and or software. Requirements for the implementation of SEP can originate from a number of sources, and this International Standard has been developed to assist in the certification of SEP that fulfil the requirements of ISO/IEC 29110‑4-m, Profile Specifications. The contents of this document can also be used to support certification of SEP that are based on other sets of specified SEP requirements. This document is intended for use by bodies that carry out audit and certification of SEP for VSEs. It gives generic requirements for such certification bodies performing audit and certification in the field of SEP for VSEs. Such bodies are referred to as certification bodies. This wording is not intended to be an obstacle to the use of this document by bodies with other designations that undertake activities covered by the scope of this document. Indeed, this document is intended to be usable by anyone involved in the assessment of SEP for VSEs. Certification activities involve the audit of a VSE's SEP. The form of attestation of conformity of a VSE's SEP to a specific lifecycle profile standard setting the applicable SEP (for example ISO/IEC 29110‑4-1 or ISO/IEC 29110‑4-3) or other specified requirements are normally a certification document or a certificate. This certification is outside the scope of ISO/IEC 29169 to the assessment to process quality characteristics and organizational maturity, and does not cover the results of process assessment. ISO/IEC 29110-3-3 describes such a scheme. It is for the VSE being certified to develop its own processes (including ISO/IEC 29110‑4-m SEP), other sets of specified SEP requirements, other processes and it is for the VSE to decide how the various components of these will be arranged. It is therefore for certification bodies that operate in accordance with this document to take into account the culture and practices of their clients with respect to the implementation of SEP, including, if applicable, within the wider organization.
Ingénierie des systèmes et du logiciel — Profils de cycle de vie pour très petits organismes (TPO) — Partie 3-2: Programme de certification de la conformité
General Information
Relations
Standards Content (Sample)
INTERNATIONAL ISO/IEC
STANDARD 29110-3-2
First edition
2018-04
Systems and software engineering —
Lifecycle profiles for Very Small
Entities (VSEs) —
Part 3-2:
Conformity certification scheme
Ingénierie des systèmes et du logiciel — Profils de cycle de vie pour
très petits organismes (TPO) —
Partie 3-2: Programme de certification de la conformité
Reference number
©
ISO/IEC 2018
© ISO/IEC 2018
All rights reserved. Unless otherwise specified, or required in the context of its implementation, no part of this publication may
be reproduced or utilized otherwise in any form or by any means, electronic or mechanical, including photocopying, or posting
on the internet or an intranet, without prior written permission. Permission can be requested from either ISO at the address
below or ISO’s member body in the country of the requester.
ISO copyright office
CP 401 • Ch. de Blandonnet 8
CH-1214 Vernier, Geneva
Phone: +41 22 749 01 11
Fax: +41 22 749 09 47
Email: copyright@iso.org
Website: www.iso.org
Published in Switzerland
ii © ISO/IEC 2018 – All rights reserved
Contents Page
Foreword .v
Introduction .vi
1 Scope . 1
2 Normative references . 2
3 Terms and definitions . 2
4 Symbols and abbreviated terms . 2
5 General requirements . 3
5.1 General . 3
5.2 Management of impartiality . 3
6 Structural requirements . 3
7 Resource requirements . 3
7.1 Certification body personnel . 3
7.1.1 General. 3
7.1.2 Management of competence for personnel involved in the certification process . 3
7.1.3 Contract with the personnel . 3
7.1.4 Personal attributes . . 3
7.1.5 Generic SEP competence requirements . 4
7.1.6 Competence requirements for Personnel granting certification . 4
7.1.7 Competence requirements for SEP auditors. 5
7.2 Resources for evaluation . 7
8 Process requirements . 7
8.1 General . 7
8.2 Application . 7
8.3 Application review . 8
8.4 Evaluation . 8
8.4.1 Evaluation Plan . . . 8
8.4.2 Audit plan . 8
8.4.3 Audit team selection and assignments .10
8.4.4 Determining audit time .10
8.4.5 Multi-site sampling .11
8.4.6 Communication of audit team tasks.11
8.4.7 Communication concerning audit team members .11
8.4.8 Communication of audit plan.11
8.4.9 Conducting on-site and remote audits .11
8.4.10 Initial certification audit .15
8.4.11 Initial certification audit conclusions .16
8.4.12 Personnel for evaluation .16
8.4.13 Information for evaluation .17
8.4.14 Resources for evaluation .17
8.4.15 Use of evaluations results completed prior to the application for certification .17
8.4.16 Nonconformities .17
8.4.17 Additional evaluation tasks .17
8.4.18 Results of evaluation .17
8.5 Review .17
8.6 Certification decision .17
8.6.1 General.17
8.6.2 Actions prior to making a decision .17
8.7 Certification documentation .18
8.8 Directory of certified VSEs .18
8.9 Surveillance.18
8.10 Changes affecting certification .18
© ISO/IEC 2018 – All rights reserved iii
8.11 Termination, reduction, suspension or withdrawal of certification .19
8.12 Records .19
8.13 Complaints and appeals .19
9 Management system requirements .19
Annex A (informative) Considerations for the audit programme, scope or plan .20
Bibliography .22
iv © ISO/IEC 2018 – All rights reserved
Foreword
ISO (the International Organization for Standardization) and IEC (the International Electrotechnical
Commission) form the specialized system for worldwide standardization. National bodies that are
members of ISO or IEC participate in the development of International Standards through technical
committees established by the respective organization to deal with particular fields of technical
activity. ISO and IEC technical committees collaborate in fields of mutual interest. Other international
organizations, governmental and non-governmental, in liaison with ISO and IEC, also take part in the
work. In the field of information technology, ISO and IEC have established a joint technical committee,
ISO/IEC JTC 1.
The procedures used to develop this document and those intended for its further maintenance are
described in the ISO/IEC Directives, Part 1. In particular the different approval criteria needed for
the different types of document should be noted. This document was drafted in accordance with the
editorial rules of the ISO/IEC Directives, Part 2 (see www .iso .org/directives).
Attention is drawn to the possibility that some of the elements of this document may be the subject
of patent rights. ISO and IEC shall not be held responsible for identifying any or all such patent
rights. Details of any patent rights identified during the development of the document will be in the
Introduction and/or on the ISO list of patent declarations received (see www .iso .org/patents).
Any trade name used in this document is information given for the convenience of users and does not
constitute an endorsement.
For an explanation on the voluntary nature of standards, the meaning of ISO specific terms and
expressions related to conformity assessment, as well as information about ISO's adherence to the WTO
principles in the Technical Barriers to Trade (TBT) see the following URL: Foreword - Supplementary
information.
This document was prepared by Joint Technical Committee ISO/IEC JTC 1, Information technology,
Subcommittee SC 7, Software and systems engineering.
A list of all parts in the ISO/IEC 29110 series can be found on the ISO website.
© ISO/IEC 2018 – All rights reserved v
Introduction
Very Small Entities (VSEs) around the world are creating valuable products and services. For the
purpose of ISO/IEC 29110, a Very Small Entity (VSE) is an enterprise, an organization, a department
or a project having up to 25 people. Since many VSEs develop and/or maintain system elements and
software components used in systems, or sold to be used by others, a recognition of VSEs as suppliers of
high quality products is required.
According to the Organization for Economic Co-operation and Development (OECD) SME and
Entrepreneurship Outlook report (2005) ‘Small and Medium Enterprises (SMEs), i.e. Enterprises
which employ fewer than 250 persons, constitute the dominant form of business organization in all
countries world-wide, accounting for o
 ...








Questions, Comments and Discussion
Ask us and Technical Secretary will try to provide an answer. You can facilitate discussion about the standard in here.